In Linaro Automated Validation Architecture (LAVA) before...
Moderate severity
Unreviewed
Published
Nov 18, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Nov 18, 2022
Published to the GitHub Advisory Database
Nov 18, 2022
Last updated
Jan 27, 2023
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.
References